peter bassill · operator
$ cve CVE-2009-1123 JSON

CVE-2009-1123 KEV

7.8
HIGH · CVSS 3.1 · EPSS 4.9% (pctl 92)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS4.88% — more likely to be exploited than 92% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploitnone known
Published2009-06-10
Last modified2026-06-16

CISA KEV

NameMicrosoft Windows Improper Input Validation Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productMicrosoft / Windows
Ransomware usenone reported

Affected (5)

VendorProduct
microsoftwindows 2000
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp

References

→ the Explorer  ·  watch your stack  ·  NVD